MySITE SQL Injection and Cross-Site Scripting Vulnerabilities

Wednesday, October 6, 2010


MySITE is a PHP-based content management application. The application is exposed to multiple issues because it fails to sufficiently sanitize user-supplied input. 1) A cross-site scripting issue that affects the "query" parameter in the "portal/modules.php" script. 2) A SQL injection issue that affects the "pid" parameter of the "print.php" script.

Ref: http://www.securityfocus.com/archive/1/513968

10.40.27 - CVE: Not Available
Platform: Web Application - Cross Site Scripting

0 comments:

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share